Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2544▼ 345 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
650 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.59% | — | Microsoft Python | 29/12/2023 | 19/8/2026 | Visual Studio Code Python Extension Remote Code Execution Vulnerability | |
| Modificada | Crítica (9.8) | 1.2% | — | Micropython | 29/12/2023 | 17/6/2026 | A vulnerability was found in MicroPython up to 1.21.0. It has been classified as critical. Affected is the function slice_indices of the file objslice.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Crítica (9.8) | 0.89% | — | Micropython | 29/12/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in MicroPython 1.21.0/1.22.0-preview. Affected by this issue is the function poll_set_add_fd of the file extmod/modselect.c. The manipulation leads to use after free. The exploit has been disclosed to the public and may be used. The patch is identified… | |
| Modificada | Media (4.9) | 1.3% | — | Python | 8/12/2023 | 31/7/2026 | An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed in CPython 3.12.1 and does not affect other stable releases. When using the `extra_groups=` parameter with an empty list as a value (ie `extra_groups=[]`) the logic regressed to not call `setgroups(0, NULL)` before calling… | |
| Modificada | Alta (7.5) | 1.1% | — | Python PillowFedoraproject Fedora | 3/11/2023 | 17/6/2026 | An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument. | |
| Modificada | Media (6.5) | 0.36% | — | Elastic Sharepoint Online Python Connector | 26/10/2023 | 17/6/2026 | An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharepoint site then that user would have read permissions to all content on the Sharepoint site through… | |
| Modificada | Media (4.2) | 0.54% | — | Python Urllib3Fedoraproject Fedora | 17/10/2023 | 17/6/2026 | urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had its method changed from one that could accept a request body (like `POST`) to `GET` as is required by HTTP RFCs.… | |
| Modificada | Media (6.1) | 0.52% | — | Python Urllib3 | 15/10/2023 | 17/6/2026 | urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because… | |
| Modificada | Alta (8.1) | 1.4% | — | Python Urllib3Debian LinuxFedoraproject Fedora | 4/10/2023 | 17/6/2026 | urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP… | |
| Modificada | Media (6.6) | 0.63% | — | Python WiremockWiremock StudioWiremockWiremock Docker | 6/9/2023 | 17/6/2026 | WireMock is a tool for mocking HTTP services. The proxy mode of WireMock, can be protected by the network restrictions configuration, as documented in Preventing proxying to and recording from specific target addresses. These restrictions can be configured using the domain names, and in such a case the configuration… | |
| Modificada | Media (6.5) | 1.1% | — | Gitpython Project Gitpython | 30/8/2023 | 17/6/2026 | GitPython is a python library used to interact with Git repositories. In order to resolve some git references, GitPython reads files from the `.git` directory, in some places the name of the file being read is provided by the user, GitPython doesn't check if this file is located outside the `.git` directory. This… | |
| Modificada | Alta (7.7) | 0.68% | — | Zope Restrictedpython | 30/8/2023 | 17/6/2026 | RestrictedPython is a restricted execution environment for Python to run untrusted code. Python's "format" functionality allows someone controlling the format string to "read" all objects accessible through recursive attribute lookup and subscription from objects he can access. This can lead to critical information… | |
| Modificada | Alta (7.8) | 0.51% | — | Gitpython Project Gitpython | 28/8/2023 | 17/6/2026 | GitPython is a python library used to interact with Git repositories. When resolving a program, Python/Windows look for the current working directory, and after that the PATH environment. GitPython defaults to use the `git` command, if a user runs GitPython from a repo has a `git.exe` or `git` executable, that program… | |
| Modificada | Media (5.3) | 0.80% | — | Python | 25/8/2023 | 17/6/2026 | An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there… | |
| Modificada | Alta (7.5) | 2.6% | — | PythonNetapp Active IQ Unified Manager | 23/8/2023 | 17/6/2026 | An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which an application would have rejected a filename for security reasons in Python 3.10.x or earlier, but… | |
| Modificada | Media (5.9) | 1.3% | — | PythonDebian LinuxNetapp Active IQ Unified ManagerNetapp Converged Systems Advisor Agent | 22/8/2023 | 17/6/2026 | An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest. | |
| Modificada | Crítica (9.8) | 5.1% | — | PythonDebian Linux | 22/8/2023 | 17/6/2026 | An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities. | |
| Modificada | Media (6.5) | 1.7% | — | PythonNetapp Active IQ Unified Manager | 22/8/2023 | 17/6/2026 | read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format. | |
| Modificada | Alta (7.5) | 1.8% | — | PythonDebian Linux | 22/8/2023 | 17/6/2026 | A use-after-free exists in Python through 3.9 via heappushpop in heapq. | |
| Modificada | Media (5.3) | 1.7% | — | Python | 15/8/2023 | 17/6/2026 | An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the _asyncio._swap_current_task component. NOTE: this is disputed by the vendor because (1) neither 3.7 nor any other release is affected (it is a bug in some 3.12 pre-releases); (2) there are no common scenarios in which an… | |
| Modificada | Crítica (9.8) | 1.2% | — | Gitpython Project Gitpython | 11/8/2023 | 17/6/2026 | GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439. | |
| Modificada | Alta (7.3) | 0.17% | — | Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+25 | 11/8/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.18% | — | Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+25 | 11/8/2023 | 17/6/2026 | Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.9) | 0.85% | — | Zope Restrictedpython | 11/7/2023 | 17/6/2026 | RestrictedPython is a tool that helps to define a subset of the Python language which allows users to provide a program input into a trusted environment. RestrictedPython does not check access to stack frames and their attributes. Stack frames are accessible within at least generators and generator expressions, which… | |
| Modificada | Alta (7.5) | 1.6% | — | Python | 25/6/2023 | 17/6/2026 | The legacy email.utils.parseaddr function in Python through 3.11.4 allows attackers to trigger "RecursionError: maximum recursion depth exceeded while calling a Python object" via a crafted argument. This argument is plausibly an untrusted value from an application's input data that was supposed to contain a name and… |